CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2011-1335

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 6, 7, and 8 before 8.1.1 allows remote attackers to inject arbitrary web script or HTML via vectors related to the "address book and user list functions."

    Published: 29 Jun 2011
    4.3
    Medium

    CVE-2011-2345

    Last Modified: 11 Apr 2025

    The NPAPI implementation in Google Chrome before 12.0.742.112 does not properly handle strings, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.

    Published: 29 Jun 2011
    4.3
    Medium

    CVE-2011-1334

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in Cybozu Office 6, Cybozu Garoon 2.0.0 through 2.1.3, Cybozu Dezie before 6.1, Cybozu MailWise before 3.1, and Cybozu Collaborex before 1.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to "downloading graphic files from the mail system."

    Published: 29 Jun 2011
    7.5
    High

    CVE-2011-2181

    Last Modified: 11 Apr 2025

    Multiple SQL injection vulnerabilities in A Really Simple Chat (ARSC) 3.3-rc2 allow remote attackers to execute arbitrary SQL commands via the (1) arsc_user parameter to base/admin/edit_user.php, (2) arsc_layout_id parameter in base/admin/edit_layout.php, or (3) arsc_room parameter to base/admin/edit_room.php.

    Published: 29 Jun 2011
    6.8
    Medium

    CVE-2011-2346

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG fonts.

    Published: 29 Jun 2011
    6.8
    Medium

    CVE-2011-2347

    Last Modified: 11 Apr 2025

    Google Chrome before 12.0.742.112 does not properly handle Cascading Style Sheets (CSS) token sequences, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.

    Published: 29 Jun 2011
    6.8
    Medium

    CVE-2011-2351

    Last Modified: 11 Apr 2025

    Use-after-free vulnerability in Google Chrome before 12.0.742.112 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors involving SVG use elements.

    Published: 29 Jun 2011
    4.3
    Medium

    CVE-2011-2470

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in chat/base/admin/login.php in A Really Simple Chat (ARSC) 3.3-rc2 allows remote attackers to inject arbitrary web script or HTML via the arsc_message parameter.

    Published: 29 Jun 2011
    6.9
    Medium

    CVE-2011-2504

    Last Modified: 11 Apr 2025

    Untrusted search path vulnerability in x11perfcomp in XFree86 x11perf before 1.5.4 allows local users to gain privileges via unspecified Trojan horse code in the current working directory.

    Published: 29 Jun 2011
    4
    Medium

    CVE-2011-3387

    Last Modified: 11 Apr 2025

    The class file parser in IBM Java 1.4.2 SR13 FP9 allows remote authenticated users to cause a denial of service (memory consumption or an infinite loop) via a crafted attribute length field in a class file, related to validation of a length field at the wrong time, a different vulnerability than CVE-2011-0311.

    Published: 29 Jun 2011
    7.5
    High

    CVE-2011-2528

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in (1) Zope 2.12.x before 2.12.19 and 2.13.x before 2.13.8, as used in Plone 4.x and other products, and (2) PloneHotfix20110720 for Plone 3.x allows attackers to gain privileges via unspecified vectors, related to a "highly serious vulnerability." NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-0720.

    Published: 28 Jun 2011
    3.3
    Low

    CVE-2011-4116

    Last Modified: 4 Aug 2025

    _is_safe in the File::Temp module for Perl does not properly handle symlinks.

    Published: 27 Jun 2011
    1.9
    Low

    CVE-2011-2204

    Last Modified: 11 Apr 2025

    Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.17, when the MemoryUserDatabase is used, creates log entries containing passwords upon encountering errors in JMX user creation, which allows local users to obtain sensitive information by reading a log file.

    Published: 27 Jun 2011
    6.8
    Medium

    CVE-2011-0213

    Last Modified: 11 Apr 2025

    Buffer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG file.

    Published: 24 Jun 2011
    7.8
    High

    CVE-2011-0196

    Last Modified: 11 Apr 2025

    AirPort in Apple Mac OS X 10.5.8 allows remote attackers to cause a denial of service (out-of-bounds read and reboot) via Wi-Fi frames on the local wireless network.

    Published: 24 Jun 2011
    5.9
    Medium

    CVE-2011-0199

    Last Modified: 11 Apr 2025

    The Certificate Trust Policy component in Apple Mac OS X before 10.6.8 does not perform CRL checking for Extended Validation (EV) certificates that lack OCSP URLs, which might allow man-in-the-middle attackers to spoof an SSL server via a revoked certificate.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0200

    Last Modified: 11 Apr 2025

    Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.

    Published: 24 Jun 2011
    7.5
    High

    CVE-2011-0201

    Last Modified: 11 Apr 2025

    Off-by-one error in the CoreFoundation framework in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a CFString object that triggers a buffer overflow.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0202

    Last Modified: 11 Apr 2025

    Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.

    Published: 24 Jun 2011
    5
    Medium

    CVE-2011-0203

    Last Modified: 11 Apr 2025

    Absolute path traversal vulnerability in xftpd in the FTP Server component in Apple Mac OS X before 10.6.8 allows remote attackers to list arbitrary directories by using the root directory as the starting point of a recursive listing.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0204

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted TIFF image.

    Published: 24 Jun 2011
    5
    Medium

    CVE-2011-0207

    Last Modified: 11 Apr 2025

    The MobileMe component in Apple Mac OS X before 10.6.8 uses a cleartext HTTP session for the Mail application to read e-mail aliases, which allows remote attackers to obtain potentially sensitive alias information by sniffing the network.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0208

    Last Modified: 11 Apr 2025

    QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0209

    Last Modified: 11 Apr 2025

    Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0210

    Last Modified: 11 Apr 2025

    QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.

    Published: 24 Jun 2011
    5
    Medium

    CVE-2011-1409

    Last Modified: 11 Apr 2025

    Frams's Fast File EXchange (F*EX, aka fex) 20100208, and possibly other versions before 20110610, allows remote attackers to bypass authentication and upload arbitrary files via a request that lacks an authentication ID.

    Published: 24 Jun 2011
    9.3
    Critical

    CVE-2011-1908

    Last Modified: 11 Apr 2025

    Integer overflow in the Type 1 font decoder in the FreeType engine in Foxit Reader before 4.0.0.0619 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted font in a PDF document.

    Published: 24 Jun 2011
    8.5
    High

    CVE-2011-2193

    Last Modified: 11 Apr 2025

    Multiple buffer overflows in Terascale Open-Source Resource and Queue Manager (aka TORQUE Resource Manager) 2.x before 2.4.14, 2.5.x before 2.5.6, and 3.x before 3.0.2 allow (1) remote authenticated users to gain privileges via a long Job_Name field in a qsub command to the server, and might allow (2) local users to gain privileges via vectors involving a long host variable in pbs_iff.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0198

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in Apple Type Services (ATS) in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code via a crafted embedded TrueType font.

    Published: 24 Jun 2011
    7.5
    High

    CVE-2011-0206

    Last Modified: 11 Apr 2025

    Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.

    Published: 24 Jun 2011
    6.4
    Medium

    CVE-2011-0212

    Last Modified: 11 Apr 2025

    servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.

    Published: 24 Jun 2011
    4.9
    Medium

    CVE-2011-1132

    Last Modified: 11 Apr 2025

    The IPv6 implementation in the kernel in Apple Mac OS X before 10.6.8 allows local users to cause a denial of service (NULL pointer dereference and reboot) via vectors involving socket options.

    Published: 24 Jun 2011
    9.3
    Critical

    CVE-2011-2194

    Last Modified: 11 Apr 2025

    Integer overflow in the XSPF playlist parser in VideoLAN VLC media player 0.8.5 through 1.1.9 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors that trigger a heap-based buffer overflow.

    Published: 24 Jun 2011
    2.1
    Low

    CVE-2011-0197

    Last Modified: 11 Apr 2025

    App Store in Apple Mac OS X before 10.6.8 creates a log entry containing a user's AppleID password, which might allow local users to obtain sensitive information by reading a log file, as demonstrated by a log file that has non-default permissions.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0205

    Last Modified: 11 Apr 2025

    Heap-based buffer overflow in ImageIO in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted JPEG2000 image.

    Published: 24 Jun 2011
    6.8
    Medium

    CVE-2011-0211

    Last Modified: 11 Apr 2025

    Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted movie file.

    Published: 24 Jun 2011
    8.3
    High

    CVE-2011-2497

    Last Modified: 11 Apr 2025

    Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size value within the command header of a Logical Link Control and Adaptation Protocol (L2CAP) configuration request, leading to a buffer overflow.

    Published: 24 Jun 2011
    4
    Medium

    CVE-2011-2511

    Last Modified: 11 Apr 2025

    Integer overflow in libvirt before 0.9.3 allows remote authenticated users to cause a denial of service (libvirtd crash) and possibly execute arbitrary code via a crafted VirDomainGetVcpus RPC call that triggers memory corruption.

    Published: 24 Jun 2011
    4.3
    Medium

    CVE-2011-2485

    Last Modified: 11 Apr 2025

    The gdk_pixbuf__gif_image_load function in gdk-pixbuf/io-gif.c in gdk-pixbuf before 2.23.5 does not properly handle certain return values, which allows remote attackers to cause a denial of service (memory consumption) via a crafted GIF image file.

    Published: 23 Jun 2011
    4.3
    Medium

    CVE-2011-2192

    Last Modified: 11 Apr 2025

    The Curl_input_negotiate function in http_negotiate.c in libcurl 7.10.6 through 7.21.6, as used in curl and other products, always performs credential delegation during GSSAPI authentication, which allows remote servers to impersonate clients via GSSAPI requests.

    Published: 23 Jun 2011
    5
    Medium

    CVE-2011-1173

    Last Modified: 11 Apr 2025

    The econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.39 on the x86_64 platform allows remote attackers to obtain potentially sensitive information from kernel stack memory by reading uninitialized data in the ah field of an Acorn Universal Networking (AUN) packet.

    Published: 22 Jun 2011
    4.3
    Medium

    CVE-2011-1330

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in WeblyGo 5.0 Pro/LE, 5.02 Pro/LE, 5.03 Pro/LE, 5.04 Pro/LE, and 5.10 Pro/LE allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jun 2011
    5.5
    Medium

    CVE-2011-2206

    Last Modified: 11 Apr 2025

    XMLParser.pm in DJabberd before 0.85 allows remote authenticated users to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML external entity declaration in conjunction with an entity reference, a different vulnerability than CVE-2011-1757.

    Published: 22 Jun 2011
    5
    Medium

    CVE-2011-2532

    Last Modified: 11 Apr 2025

    The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data.

    Published: 22 Jun 2011
    5
    Medium

    CVE-2011-2205

    Last Modified: 11 Apr 2025

    Prosody before 0.8.1 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

    Published: 22 Jun 2011
    9.3
    Critical

    CVE-2011-2530

    Last Modified: 11 Apr 2025

    Buffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardware Installation Tool 1.0.5.1 and earlier in Rockwell Automation RSLinx Classic before 2.58 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed .eds file.

    Published: 22 Jun 2011
    4.3
    Medium

    CVE-2011-2531

    Last Modified: 11 Apr 2025

    Prosody 0.8.x before 0.8.1, when MySQL is used, assigns an incorrect data type to the value column in certain tables, which might allow remote attackers to cause a denial of service (data truncation) by sending a large amount of data.

    Published: 22 Jun 2011
    5
    Medium

    CVE-2011-2377

    Last Modified: 11 Apr 2025

    Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird before 3.1.11, and SeaMonkey through 2.0.14 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace image.

    Published: 22 Jun 2011
    9.3
    Critical

    CVE-2011-2685

    Last Modified: 11 Apr 2025

    Stack-based buffer overflow in the Lotus Word Pro import filter in LibreOffice before 3.3.3 allows remote attackers to execute arbitrary code via a crafted .lwp file.

    Published: 22 Jun 2011
    7.5
    High

    CVE-2011-2500

    Last Modified: 11 Apr 2025

    The host_reliable_addrinfo function in support/export/hostname.c in nfs-utils before 1.2.4 does not properly use DNS to verify access to NFS exports, which allows remote attackers to mount filesystems by establishing crafted DNS A and PTR records.

    Published: 22 Jun 2011